Files
awoooi/docs/security/security-finding-kali-sample.snapshot.json
Your Name 9e15fd08b3
All checks were successful
CD Pipeline / tests (push) Successful in 1m39s
Code Review / ai-code-review (push) Successful in 15s
CD Pipeline / build-and-deploy (push) Successful in 5m19s
CD Pipeline / post-deploy-checks (push) Successful in 2m11s
feat(web): land iwooos security posture surfaces
2026-05-25 20:35:52 +08:00

26 lines
1.1 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
{
"schema_version": "security_finding_v1",
"finding_id": "sample-kali-112-harbor-scan-failure-20260513",
"scan_run_id": "sample-kali-112-contract-only-20260513",
"scanner": "kali",
"scanner_version": "nmap:7.99;nikto:2.6.0;nuclei:3.8.0",
"asset_key": "tool:harbor-image-scan",
"target_type": "tool",
"target": "harbor_image_scan_redacted",
"category": "supply_chain",
"severity": "MEDIUM",
"confidence": "MEDIUM",
"status": "new",
"recommended_mode": "warn",
"evidence_ref": "docs/security/KALI-INTEGRATION-STATUS.md#4-仍未完成的整合",
"summary": "Kali 112 週期性 Harbor image scan 目前有 target、project、auth 或 certificate chain 不一致的跡象;此 sample 只作為契約驗證,不代表 runtime ingestion 已啟用。",
"recommended_action": "先修正 Harbor target/project/credential/certificate chain確認 scanner evidence 穩定後再納入正式 ingestion不得自動修復或阻擋部署。",
"owner_team": "security-commander",
"labels": {
"source_host": "host:kali-112",
"runtime_ingested": "false",
"redacted": "true",
"blocking": "false"
}
}